Skip to content
View chu0119's full-sized avatar

Highlights

  • Pro

Block or report chu0119

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
chu0119/README.md

星川 xingchuan — Security Engineering

星川 / xingchuan

Security Researcher & Tool Builder

把安全信号转化为可执行的检测、响应与工程化工具。
Turning security signals into practical detection, response, and engineering systems.

Offensive Security  ·   Threat Detection  ·   Incident Response  ·   AI Automation

研究方向 · Focus

01 // 攻防与漏洞研究
Offensive Security & Vulnerability Research

面向授权场景的漏洞发现、验证与治理。

02 // 检测、研判与响应
Detection, Threat Intelligence & IR

从日志与流量中提取线索,形成可解释的安全结论。

03 // AI 安全自动化
AI-powered Security Tooling

用智能工作流缩短侦察、分析、处置与报告链路。

代表项目 · Selected Work

HTML · Security Workflow UX

把内网评估命令与结果整理成清晰、可复用的工作流。
Usable command building and report parsing for practical assessment.

TypeScript · AI Threat Analysis

将原始 Web 日志转化为可解释的威胁研判结果。
AI-assisted web-log analysis from raw events to security verdicts.

Python · Exposure Defense

面向公开泄露风险的发现、只读验证与持续监控。
Defensive exposure discovery and validation across AI platforms.

Python · Detection Engineering

用规则、威胁情报和攻击链视角完成结构化日志研判。
ATT&CK-aware detection, investigation, and reporting workflows.

TypeScript · Threat Intelligence

聚合多源情报,对 IP 与域名形成加权研判。
Multi-source threat intelligence with fast, explainable verdicts.

Python · Incident Response

为失陷主机提供快速网络隔离与生效验证。
Fast network isolation and verification for incident response.

能力矩阵 · Capabilities

Security Engineering Detection & Response Development Platforms
漏洞评估
授权测试
漏洞治理
日志与流量分析
威胁情报
应急响应
Python
TypeScript
LLM Agent
Linux · Docker
MySQL · Redis
Security Toolchains

经历与认可 · Experience & Recognition

2023 — Now Security Engineering Practice — 安全运营、漏洞治理、日志分析与自动化工具开发。
Recognition National & Provincial — 企业信息安全、信息安全管理评估与 AI 信息素养相关赛事经历。
Principle Build for real workflows — 持续把侦察、检测、响应和报告沉淀为可复用工具链。

开源数据 · Open Source Signal

公开仓库、Star、Fork 与主要语言数据

工程协作与项目数据

主要编程语言分布

Metrics are generated daily from explicitly public repositories through the GitHub API and stored here. No private activity or third-party stats image service is used.

最近动态 · Recent Activity

协作 · Collaboration

欢迎围绕安全工具、威胁检测、应急响应与 AI 安全自动化交流协作。
Open to collaboration on practical security tooling, detection engineering, incident response, and AI-assisted security workflows.

查看全部公开项目 · Follow @chu0119

All security research and tooling is intended for authorized testing, defensive research, and education.

Pinned Loading

  1. tg-monitor-v2 tg-monitor-v2 Public

    听风追影 Telegram 群组实时监控、关键词告警、数据分析与可视化大屏系统

    Python 5 1

  2. zhidun zhidun Public template

    星川智盾 - AI 驱动的网站日志安全分析系统 | Cyberpunk-themed AI-powered web log security analyzer

    TypeScript 23 2

  3. DarkForest-Hunter DarkForest-Hunter Public

    🌲 DarkForest Hunter — 公开仓库泄露 AI API Key 扫描与验证,覆盖 35 个 AI 平台(DeepSeek / Kimi / 智谱 / Qwen / OpenAI / Gemini / Claude / Groq / OpenRouter 等),只读优先验证 + 余额查询,24/7 watch + 高价值邮件告警;内嵌 mihomo 多 IP 代理与 heade…

    Python 15 5

  4. fscan-toolkit fscan-toolkit Public

    fscan 图形化管理工具套件 — 命令生成器 + 报告解析器,零依赖纯静态 HTML

    HTML 25

  5. edusrc-hunter edusrc-hunter Public

    EDUSRC教育漏洞挖掘技能 - 通过Burp MCP进行信息收集、资产发现、漏洞扫描和报告生成,专注于真实可上报的高危漏洞

    Shell 4

  6. xingchuan-ti xingchuan-ti Public

    星川威胁情报助手 - 划词识别 IP/域名,多源威胁情报加权研判 + 一键跳转国内主流情报平台

    TypeScript 10 3